Free 312-50v13 Exam Braindumps (page: 35)

Page 11 of 79

Kevin, a professional hacker, wants to penetrate CyberTech Inc’s network. He employed a technique, using which he encoded packets with Unicode characters. The company’s IDS cannot recognize the packets, but the target web server can decode them.

What is the technique used by Kevin to evade the IDS system?

  1. Session splicing
  2. Urgency flag
  3. Obfuscating
  4. Desynchronization

Answer(s): C



Suppose that you test an application for the SQL injection vulnerability. You know that the backend database is based on Microsoft SQL Server. In the login/password form, you enter the following credentials:



Based on the above credentials, which of the following SQL commands are you expecting to be executed by the server, if there is indeed an SQL injection vulnerability?

  1. select * from Users where UserName = ‘attack’ ’ or 1=1 -- and UserPassword = ‘123456’
  2. select * from Users where UserName = ‘attack’ or 1=1 -- and UserPassword = ‘123456’
  3. select * from Users where UserName = ‘attack or 1=1 -- and UserPassword = ‘123456’
  4. select * from Users where UserName = ‘attack’ or 1=1 --’ and UserPassword = ‘123456’

Answer(s): A



Which of the following commands checks for valid users on an SMTP server?

  1. RCPT
  2. CHK
  3. VRFY
  4. EXPN

Answer(s): C



Bella, a security professional working at an IT firm, finds that a security breach has occurred while transferring important files. Sensitive data, employee usernames, and passwords are shared in plaintext, paving the way for hackers to perform successful session hijacking. To address this situation, Bella implemented a protocol that sends data using encryption and digital certificates.

Which of the following protocols is used by Bella?

  1. FTPS
  2. FTP
  3. HTTPS
  4. IP

Answer(s): A






Post your Comments and Discuss EC-Council 312-50v13 exam with other Community members:

312-50v13 Exam Discussions & Posts